WO2026124706 - VERFAHREN UND SYSTEM ZUR SICHEREN DATENVERARBEITUNG IN EINER UNSICHEREN LAUFZEITUMGEBUNG
National phase entry is expected:
Publication Number
WO/2026/124706
Publication Date
18.06.2026
International Application No.
PCT/DE2024/101072
International Filing Date
13.12.2024
Title **
[German]
VERFAHREN UND SYSTEM ZUR SICHEREN DATENVERARBEITUNG IN EINER UNSICHEREN LAUFZEITUMGEBUNG
[English]
METHOD AND SYSTEM FOR SECURE DATA PROCESSING IN AN INSECURE RUNTIME ENVIRONMENT
[French]
PROCÉDÉ ET SYSTÈME DE TRAITEMENT SÉCURISÉ DE DONNÉES DANS UN ENVIRONNEMENT D'EXÉCUTION NON SÉCURISÉ
Applicants **
DEUTSCHE BAHN AKTIENGESELLSCHAFT
Inventors
LEHMANN, Jens
Application details
| Total Number of Claims/PCT | * |
| Number of Independent Claims | * |
| Number of Priorities | * |
| Number of Multi-Dependent Claims | * |
| Number of Drawings | * |
| Pages for Publication | * |
| Number of Pages with Drawings | * |
| Pages of Specification | * |
| * | |
| Number of Office Actions | * |
| * | |
International Searching Authority |
EPO
* |
| Recordal of a Change of the Applicant's Name/Address |
Change of Applicant's Name and Address
* |
| Type of Assignment |
The Standard Agent's Assignment
* |
| Applicant's Legal Status |
Legal Entity
* |
| * | |
| * | |
| * | |
| * | |
| * | |
| Entry into National Phase under |
Chapter I
* |
| Patent Delivery |
Send the Letters Patent by Courier
* |
| Translation |
|
* The data is based on automatic recognition. Please verify and amend if necessary.
** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.
Quotation for National Phase entry
| Country | Stages | Total | |
|---|---|---|---|
| China | Filing, Examination, Granting | 1806 | |
| EPO | Filing, Examination, Granting | 8159 | |
| Japan | Filing, Examination, Granting | 1828 | |
| South Korea | Filing, Examination, Granting | 1280 | |
| USA | Filing, Examination, Granting | 5340 |

Total:
18,413
Contact Us
Abstract[German]
Die Erfindung betrifft ein zur Verarbeitung von in einem betriebstechnologischen Computersystem (OT) erzeugten Primärdaten in einem unsicheren Computersystem (IT) mit einer unsicheren Laufzeitumgebung, welches die Beibehaltung eines im Kontext der Erzeugung in einem betriebstechnologischen Computersystem erworbenen ursprünglichen Sicherheits-Integritätslevels von Primärdaten auch für die aus deren Verarbeitung in einem unsicheren Computersystem resultierenden Ergebnisdaten ermöglicht. Dies wird erfindungsgemäß unter anderem dadurch erreicht, dass mittels mindestens einer ersten Laufzeitüberwachungseinheit (ITLÜ) im unsicheren Computersystem (IT) (a) die Datenverarbeitung von Kommunikations- und Entschlüsselungseinheit (ITKE) und erster Prüfeinheit (ITPR-1), (b) sowie die Datenverarbeitung von erster Prüfeinheit (ITPR-1), erster und zweiter Datenverarbeitungseinrichtungen (ITDV-1, ITDV-2), zweiter Prüfeinheit (ITPR-2), Sicherungseinheit (ITSI) sowie Sicherungs- und Prüfeinheit (ITSP) überwacht werden und jede erste Laufzeitüberwachungseinheit (ITLÜ) des unsicheren Computersystems (IT) mittels mindestens einer zweiten Laufzeitüberwachungseinheit (SILÜ) in einem sicheren Computersystem mit sicherer Laufzeitumgebung (SIL) überwacht wird.[English]
The invention relates to a method for processing primary data generated in an operating technology computer system (OT) in an insecure computer system (IT) with an insecure runtime environment, which enables an original security integrity level of primary data acquired in the context of generation in an operating technology computer system to be maintained even for the result data resulting from the processing thereof in an insecure computer system. According to the invention, this is achieved, inter alia, by virtue of the fact that (a) the data processing of the communication and decryption unit (ITKE) and the first checking unit (ITPR-1), (b) and the data processing of the first checking unit (ITPR-1), the first and second data processing devices (ITDV-1, ITDV-2), the second checking unit (ITPR-2), the back-up unit (ITSI) and the back-up and checking unit (ITSP) are monitored by means of at least one first runtime monitoring unit (ITLÜ) in the insecure computer system (IT), and each first runtime monitoring unit (ITLÜ) of the insecure computer system (IT) is monitored by means of at least one second runtime monitoring unit (SILÜ) in a secure computer system with a secure runtime environment (SIL).[French]
L'invention se rapporte à un procédé de traitement de données primaires générées dans un système informatique de technologie d'exploitation (OT) dans un système informatique (IT) non sécurisé doté d'un environnement d'exécution non sécurisé, qui permet de maintenir un niveau d'intégrité de sécurité d'origine de données primaires acquises dans le contexte de génération dans un système informatique de technologie d'exploitation même pour les données de résultat résultant de leur traitement dans un système informatique non sécurisé. Selon l'invention, ceci est obtenu entre autres grâce au fait que (a) le traitement de données de l'unité de communication et de déchiffrement (ITKE) et de la première unité de contrôle (ITPR-1), (b) et le traitement de données de la première unité de contrôle (ITPR-1), des premier et second dispositifs de traitement de données (ITDV-1, ITDV-2), de la seconde unité de contrôle (ITPR-2), de l'unité de sauvegarde (ITSI) et de l'unité de sauvegarde et de contrôle (ITSP) sont surveillés au moyen d'au moins une première unité de surveillance d'exécution (ITLÜ) dans le système informatique (IT) non sécurisé, et chaque première unité de surveillance d'exécution (ITLÜ) du système informatique (IT) non sécurisé est surveillée au moyen d'au moins une seconde unité de surveillance d'exécution (SILÜ) dans un système informatique sécurisé doté d'un environnement d'exécution sécurisé (SIL).